Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
2017-11-29T21:29:00.217
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.0 (CRITICAL)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | crucible | < 4.4.3 | Yes |
Application | atlassian | crucible | 4.5.0 | Yes |
Application | atlassian | fisheye | < 4.4.3 | Yes |
Application | atlassian | fisheye | 4.5.0 | Yes |